CVE-2026-41090
Critical · CVSS 9.3- CVSS
- 9.3
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-77
Description
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
References
Status: profiled · ingested 2026-07-23T12:00:18.000Z